VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25359 CVEsRSS

CVE-2026-4123Medium· 4.3
6d ago

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to a missing capability check on the toggle_cache() function which is hooked to the wp_a…

▾ Sunlitrwelephant01 · RW Elephant Rental InventoryEPSS 0.35%via NVD
CVE-2026-92235High· 8.1
6d ago

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a…

▾ Twilightroxnor · WP Ultimate ReviewEPSS 0.36%via NVD
CVE-2025-1281High· 8.8
6d ago

The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding,…

The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding,…

▾ TwilightSeaTheme · BM Content BuilderEPSS 0.57%via NVD
CVE-2026-6922High· 7.1
6d ago

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash…

▾ Twilightwptb · WP Table Builder – Drag & Drop Table BuilderEPSS 0.56%via NVD
CVE-2026-1645Medium· 4.4
6d ago

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output e…

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output e…

▾ Sunlitprasunsen · HostelEPSS 0.19%via NVD
CVE-2025-14487Medium· 5.3
6d ago

The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3

The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify …

▾ Sunlitkamleshyadav · HandilyEPSS 0.23%via NVD
CVE-2026-93836High· 7.2
6d ago

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. Thi…

▾ Twilightwpclever · WPC Product Bundles for WooCommerceEPSS 0.40%via NVD
CVE-2025-1280Medium· 6.5
6d ago

The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function

The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with …

▾ SunlitSeaTheme · BM Content BuilderEPSS 0.53%via NVD
CVE-2026-9004Medium· 4.3
6d ago

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This makes it possible for authenticated att…

▾ Sunlitnofearinc · WP-CRM System – Manage Clients and ProjectsEPSS 0.37%via NVD
CVE-2026-7622Medium· 4.3
6d ago

The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1

The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the…

▾ Sunlitcodexpert · ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & MoreEPSS 0.35%via NVD
CVE-2026-93778High· 7.2
6d ago

The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and o…

The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and o…

▾ Twilightjgwhite33 · WP Yelp Review SliderEPSS 0.43%via NVD
CVE-2026-95503Medium· 6.8
6d ago

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Di…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.19%via NVD
CVE-2026-92438High· 8.8
6d ago

The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form th…

The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form th…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-91827High· 7.5
6d ago

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injec…

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injec…

▾ TwilightEPSS 0.30%via NVD
CVE-2026-89412High· 7.2
6d ago

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and in…

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and in…

▾ Twilightcozmoslabs · TranslatePress – Translate Multilingual sites with AI TranslationEPSS 0.53%via NVD
CVE-2026-94504High· 7.2PoC
6d ago

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attack…

▾ Midnightkstover · Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form BuilderEPSS 0.41%via NVD
CVE-2026-88788Medium· 6.8
6d ago

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with…

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-85653Medium· 6.4
6d ago

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping.…

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping.…

▾ Sunlitajay · Contextual Related PostsEPSS 0.42%via NVD
CVE-2026-93655Medium· 6.1
6d ago

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This ma…

▾ Sunlitwpdevelop · Booking CalendarEPSS 0.37%via NVD
CVE-2026-12470High· 7.2
6d ago

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' A…

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' A…

▾ Twilightniteo · CMP – Coming Soon & Maintenance Plugin by NiteoThemesEPSS 0.33%via NVD
CVE-2026-13355Critical· 9.8PoC
6d ago

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission …

▾ AbyssalMeta Box · Meta Box Frontend SubmissionEPSS 0.44%via NVD
CVE-2026-19658Critical· 9.8PoC
6d ago

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object…

▾ AbyssalLiquidWeb · Give TributesEPSS 0.53%via NVD
CVE-2026-94493Critical· 10.0PoC
6d ago

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack …

▾ AbyssalGigatech · PDV5701EPSS 0.73%via NVD
CVE-2026-94492Medium· 6.3PoC
6d ago

A security vulnerability has been detected in Yonyou U8cloud 5.x

A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sq…

▾ TwilightYonyou · U8cloudEPSS 0.32%via NVD
CVE-2026-76974Medium· 5.3
6d ago

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled conten…

▾ SunlitSAP_SE · SAP Fiori LaunchpadEPSS 0.35%via NVD
CVE-2026-94491High· 7.3PoC
6d ago

A weakness has been identified in Yonyou KSOA 9.0

A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remote…

▾ MidnightYonyou · KSOAEPSS 0.41%via NVD
CVE-2026-93710High· 7.5
6d ago

Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup unless the f…

Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup unless the f…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-93709Medium· 5.3
6d ago

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text, while the…

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text, while the…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-93711Medium· 6.5
6d ago

Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name

Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the PSGI se…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-93712High· 7.5
6d ago

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and che…

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and che…

▾ TwilightEPSS 0.55%via NVD
CVEs tagged “nvd” — page 92 · VulnSea